An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the Key Distribution Center (KDC), which allows remote authenticated users to cause a denial of service (NULL pointer dereference) via a modified kadmin client.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade krb5 | May 7, 2019 | Jan 16, 2018 |
| Debian | — | Upgrade krb5 | Dec 19, 2022 | Jan 16, 2018 |
| Oracle Solaris | — | Upgrade security/kerberos-5/kdc to version 1.16.1.0-0.175.3.35.0.4.0 on Solaris 11.3Upgrade security/kerberos-5 to version 1.16.1.0-0.175.3.35.0.4.0 on Solaris 11.3 | Aug 24, 2018 | Jan 16, 2018 |
| Ubuntu | — | Upgrade krb5 | Nov 19, 2024 | Jan 16, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub